Security Engineer
Умения
Сертификати
Описание
Location: Sofia, Bulgaria (our Sofia office)
Working hours: Flexible
About Us:
Globe Tracker is a global IoT and supply chain technology company headquartered in Copenhagen, Denmark. We make the supply chain smart — building the hardware and software that enables real-time tracking and monitoring of containerised cargo across the world's most complex logistics networks. Our customers include some of the largest names in shipping and logistics, and we run a 24/7 global operation that never sleeps.
Security is not an afterthought at Globe Tracker — it is foundational. We are ISO/IEC 27001 certified and committed to building systems that our customers trust with their most critical operations. As we scale, we are looking for a Security Engineer who can grow with us and help us stay ahead.
The Role:
We are looking for a Security Engineer to join our engineering team in our Sofia office and own the security posture of our cloud infrastructure, identity platform and development pipelines. This is a hands-on, cross-functional role — you will work closely with our DevOps and engineering teams to embed security into everything we build and operate. You bring solid security engineering experience and a genuine understanding of how cloud and DevOps environments work from the inside.
What You Will Do:
- Own and continuously improve our cloud security posture across AWS, with a focus on practical, automated, and scalable controls.
- Own our identity and access management across Microsoft Entra ID and Keycloak — Entra ID for our corporate identities (conditional access, MFA, app registrations) and Keycloak for application and customer identity (realms, clients and roles, OIDC/OAuth2 for our applications and APIs, and single sign-on federation with customers' own identity providers). You will own how the two connect, token and secret lifecycle, and least-privilege access models across both.
- Secure our Kubernetes workloads — RBAC, network policies, admission controls, runtime security, and hardening.
- Integrate security into our CI/CD pipelines (CircleCI, GitHub) — including image scanning, secret detection, dependency auditing, and SAST/DAST tooling.
- Manage and mature our use of Lacework for CSPM, CWPP, and threat detection — tuning alerts, investigating findings, and driving remediation.
- Work with Terraform to review IaC for misconfigurations and help establish secure-by-default infrastructure patterns.
- Lead vulnerability management workflows: triage, prioritisation, communication, and tracking remediation to closure.
- Coordinate external penetration tests and drive their findings to closure; monitor and improve our external security rating (SecurityScorecard).
- Build out our logging and detection capability — AWS audit logging (CloudTrail), security findings aggregation, and the path towards SIEM/SOC.
- Act as the technical security contact for customers — answering security questionnaires and reviews, presenting our controls, and turning customer requirements into concrete improvements.
- Contribute to our ISO/IEC 27001 programme — helping maintain controls and security policies, support audits, and translate policy into technical practice.
- Respond to security incidents and alerts — investigate, contain, document, and improve.
- Act as a security partner to engineering teams — reviewing architectures, advising on secure design, and raising the security bar without slowing delivery.
- Maintain and develop security documentation, runbooks, and the team knowledge base.
What We Are Looking For:
Required:
- 2–5 years of dedicated security engineering experience (cloud security, DevSecOps, application security, or similar).
- Solid background in cloud environments — AWS is our primary platform; you understand IAM, VPCs, security groups, S3 policies, and the AWS shared responsibility model.
- Hands-on experience with identity and access management — OAuth2/OIDC, SSO, and identity federation. Experience with Microsoft Entra ID and Keycloak is a strong plus.
- Experience securing Kubernetes and containerised workloads.
- Familiarity with Infrastructure-as-Code — Terraform preferred.
- Familiarity with CI/CD security integration (GitHub Actions, CircleCI, or equivalent).
- Experience with CSPM or CWPP tooling — Lacework experience is a strong plus.
- Experience with security logging, monitoring, and incident response workflows.
- Strong communication skills — you can explain a CVE and its business impact clearly to both engineers and non-technical stakeholders.
- Comfortable working in a fast-moving, globally distributed team.
- Excellent written and spoken English.
- Prior background in DevOps or software engineering is a significant advantage — we want someone who understands how systems are built, not just how they are attacked.
Nice to Have:
- Experience with ISO/IEC 27001 implementation or audits.
- Experience handling customer security reviews or vendor security assessments.
- Hands-on experience with SIEM platforms.
- Security certifications: AWS Security Specialty, CKS (Certified Kubernetes Security Specialist), OSCP, CISSP, or similar.
- Experience with container image signing and software supply chain security (SBOM, Sigstore/Cosign).
- Background working in IoT, logistics, or critical infrastructure environments.
Why Globe Tracker:
- Work on infrastructure that is genuinely mission-critical — our systems run 24/7 across global shipping operations.
- High autonomy and ownership — you will have real impact on our security posture, not just follow a checklist.
- Collaborative engineering culture that takes security seriously at the organisational level (ISO 27001 certified).
- Modern, cloud-native stack: AWS, Kubernetes, Terraform, GitHub, CircleCI, Lacework, Keycloak, Microsoft Entra ID.
- Competitive salary and benefits package.
- Flexible working hours.
- A team that values continuous learning and professional development.
Globe Tracker is an equal opportunity employer. We welcome applicants of all backgrounds and experience levels.
История на обявата
- 10 октомври 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за Security Engineer (Cloud / Network) на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.
Само 1 обява за тази роля и ниво публикуват заплата — твърде малко за средна стойност.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.